By David Chernitzky, Co-Founder and CEO, Armour Cybersecurity | Serving organizations across Canada, the US, and beyond | Last updated August 18, 2026
Quick answer: Vendor breach response for a business starts with one question: when a vendor is breached, did the attacker reach you through that vendor’s access to your systems or data? The answer determines whether you have an operational security incident to manage alongside the vendor’s breach, and whether you have regulatory notification obligations of your own. Most organizations discover what to do in this situation by improvising under pressure. Organizations with pre-arranged vendor incident response protocols move faster, contain more effectively, and make better decisions about notification and disclosure.
Key Takeaways
- A vendor breach does not automatically mean your organization was compromised. The first step is to assess what access the vendor had to your systems and data and whether there is evidence that the attacker used that access to reach you. This assessment determines the severity of your own incident.
- Temporarily restricting or revoking vendor access as soon as a breach is confirmed is the fastest containment action available. If the attacker is using the vendor’s credentials or connection to access your environment, cutting that access stops the intrusion. If the attacker has not yet reached you, it prevents them from doing so while the vendor manages its own incident.
- Your own regulatory notification obligations may be triggered by a vendor breach independently of whether the vendor notifies its regulators. If the vendor’s breach exposed personal information that the vendor processed on your behalf, you may have obligations under PIPEDA, Quebec Law 25, HIPAA, or other applicable privacy law to assess the breach and determine whether notification is required.
- The contractual provisions in your vendor agreement determine what the vendor is obligated to tell you, when, and in what format. Vendors without breach notification obligations in their contracts may not proactively inform you of a breach, leaving you to discover it through public reporting or your own detection.
- Pre-arranged vendor incident response protocols, defined before an incident occurs, are the only way to ensure that the first call to a breached vendor reaches the right contact and initiates a coordinated response rather than an improvised one.
The First Hours: What You Need to Know Immediately
When you become aware that a vendor has experienced a security incident, the first priority is rapid triage: determining the scope of the vendor’s breach and your potential exposure. The triage questions are: What access does this vendor have to our systems and data? What is the scope of the breach, specifically which of the vendor’s systems and data are affected? Is there any indication that the attacker has used the vendor’s access to reach our environment? When did the breach occur and when was it discovered, and what might have been accessible to the attacker during that period?
These questions need to be answered quickly because the actions that follow depend on the answers. If the vendor’s breach affected systems that have no connection to your environment, the impact on your organization may be limited to reputational concerns and the vendor’s service availability. If the vendor’s breach affected systems through which the attacker could reach your environment, you have an active security incident to manage alongside the vendor’s breach, and your response timeline begins from that determination. This is the concrete version of the principle that your vendors are your attack surface: the vendor’s incident becomes yours the moment their access touches your environment.
Immediate Containment Actions
Assess and restrict vendor access
The first containment action is to review the access the vendor holds in your environment and assess whether that access needs to be temporarily restricted while the vendor’s incident is being investigated. If the vendor has administrative credentials to your systems, those credentials should be rotated or temporarily disabled. If the vendor accesses your environment through a VPN or dedicated connection, that connection should be reviewed and potentially suspended. If the vendor uses an API key or service account to integrate with your systems, those credentials should be rotated. The goal is to remove the attacker’s path to your environment through the vendor’s compromised access, without unnecessarily disrupting critical vendor services if the access was not affected by the breach.
The decision to restrict vendor access must balance security against operational continuity. Immediately revoking all access from a critical vendor whose compromise is still being assessed may cause significant operational disruption if the vendor’s service is essential to daily operations. The tiering and criticality assessment in your supplier risk program informs this decision: critical vendors have pre-arranged incident response protocols that define the access restriction procedure and the operational mitigation for service disruption during the restriction period. This is one of the practical payoffs of vendor risk tiering done in advance.
Search your environment for indicators of compromise
If the vendor had access to your systems, your security team or a forensic response partner should search your environment for indicators of compromise that may indicate the attacker reached you through the vendor’s access. Indicators to search for include unusual authentication activity from the vendor’s service accounts or credentials, unexpected network connections to external destinations through the vendor’s access path, evidence of lateral movement originating from systems the vendor accessed, and any anomalies in the logs of systems the vendor had access to during the breach window. How effectively you can run this search depends on the visibility and monitoring coverage you already have, which is exactly what a cybersecurity posture assessment establishes as your baseline before an incident forces the question. The breach window is the period from when the vendor’s compromise occurred (which may be significantly earlier than when the breach was discovered) through when the access was restricted. Evidence of compromise during this window means you have your own incident to manage.
Activate your breach response team
If indicators of compromise are found, or if the vendor’s breach created a realistic risk of data exposure even without confirmed compromise, activate your breach response team immediately. This includes your internal security leadership, legal counsel, the breach coach or incident response retainer if you have one, and executive leadership as appropriate given the potential scope. The breach response team manages the parallel workstreams: investigating your own environment, managing regulatory notification timelines, coordinating with the vendor, and communicating with stakeholders. Waiting to activate the team until compromise is confirmed loses time that cannot be recovered if regulatory notification timelines are already running.
Your Regulatory Notification Obligations
Your own regulatory notification obligations in a vendor breach scenario depend on what data the vendor processed on your behalf and what happened to it. Under PIPEDA and Quebec Law 25, if personal information that you were responsible for was exposed through the vendor’s breach, you may have notification obligations regardless of whether you were directly compromised. The vendor processed the personal information on your behalf; you remain the organization responsible for that personal information under Canadian privacy law, and managing that responsibility sits within your privacy risk management program.
The breach assessment process, which your privacy officer and legal counsel lead, determines whether the exposure creates a real risk of significant harm (PIPEDA threshold) or a risk of serious injury (Quebec Law 25 threshold) to the individuals whose information was involved. If it does, notification obligations to the regulator and to affected individuals are triggered. Quebec Law 25 requires notification to the Commission d’acces a l’information promptly and with diligence once you have reason to believe a confidentiality incident presents a risk of serious injury. Quebec sets no fixed statutory 72-hour deadline (72 hours is the GDPR clock and a common operational benchmark), but the obligation to act with diligence begins when you become aware of the vendor breach, not when you confirm your own systems were compromised. Every confidentiality incident must also be logged in your incident register regardless of whether it meets the notification threshold.
The contractual provisions in your vendor agreement determine how quickly the vendor is required to inform you of a breach affecting your data and what information they must provide. A vendor with a 24-hour breach notification obligation in its contract provides you with the information you need to begin your own assessment within the first day. A vendor with no breach notification obligation in its contract may not proactively inform you at all, leaving you dependent on public breach reporting or your own detection to learn that your data may have been exposed.
The Role of the Vendor Incident Response Protocol
A vendor incident response protocol is a pre-arranged set of procedures that defines how your organization and a specific critical vendor will coordinate in the event of a security incident affecting either party. It is developed as part of the supplier risk management program, agreed with the vendor before any incident occurs, and stored in a location accessible to the response team during an incident.
The protocol defines the communication channels and escalation contacts at the vendor for security incidents, distinguishing between general account contacts and the security and legal contacts who are actually empowered to respond to a breach. It defines the information the vendor will provide within defined timeframes: what happened, which systems and data are affected, what the vendor is doing to contain and investigate, and what additional information will be forthcoming. It defines the organization’s own response steps when notified of a vendor incident: the access restriction procedure, the compromise search protocol, the internal escalation chain, and the notification decision timeline. And it defines the evidence handling expectations for any forensic work that involves shared systems or data.
Organizations that have pre-arranged vendor incident response protocols with their critical vendors consistently experience better outcomes in vendor breach scenarios than those that improvise their response. The protocol exists precisely so the first call to the vendor does not begin with establishing who to speak to and what to ask for. Armour Cybersecurity designs vendor incident response protocols as a standard component of the Supplier Risk Management engagement.
Frequently Asked Questions
How do we find out that a vendor has been breached if they do not tell us?
Vendor breaches that are not disclosed proactively come to your attention through several channels. Public reporting, including press coverage, regulatory announcements, and the vendor’s own public statements, is the most common source. Security ratings monitoring services that track observable indicators of compromise may show anomalies in the vendor’s infrastructure before public disclosure. Threat intelligence feeds that monitor breach disclosures and dark web data may surface vendor-related information. Your own security monitoring may detect unusual activity originating from the vendor’s systems or credentials before the vendor has identified and disclosed its breach. Establishing these monitoring capabilities as part of your supplier risk program reduces the dependence on the vendor’s own disclosure as the primary source of information.
Can we sue a vendor for damages resulting from their breach?
The ability to recover damages from a vendor for a breach that affected your organization depends primarily on what the vendor contract says. A contract with no security provisions provides no contractual basis for a damages claim beyond general negligence or breach of implied warranty arguments, which are harder to pursue and less reliable in their outcomes. A contract with specific security obligations, audit rights that were exercised, and a documented failure by the vendor to meet those obligations provides a much stronger basis for a contractual damages claim. The legal strategy in any vendor breach litigation is a matter for legal counsel with expertise in technology and privacy law. The practical message for supplier risk management is that negotiating specific contractual security provisions before a breach occurs is the foundation of any post-breach recovery strategy.
What should we do if we discover the breach affected personal information we are responsible for?
Engage your privacy officer and legal counsel immediately. The breach assessment process under applicable privacy law must be completed within the applicable notification window: promptly and with diligence under Quebec Law 25 from when you became aware of an incident presenting a risk of serious injury (Quebec sets no fixed statutory deadline; 72 hours is the GDPR benchmark), and as soon as feasible under PIPEDA from when you determined a breach of security safeguards created a real risk of significant harm. The assessment determines whether the breach meets the regulatory harm threshold for mandatory notification. If it does, notifications to the relevant regulator and to affected individuals must be prepared and delivered. The assessment and notification process should be documented contemporaneously as evidence of your compliance response. Your breach response retainer or legal counsel should be engaged to manage the regulatory notification process if the breach is material.
What should be in the first communication with a breached vendor?
The first communication with a breached vendor should establish the facts you need to complete your own assessment: when the breach occurred, when it was discovered, which of the vendor’s systems were affected, specifically those through which your data or systems could be reached, whether there is any evidence that the attacker accessed your data or reached your environment through the vendor’s access, what the vendor is doing to contain the breach and investigate its scope, and what additional information the vendor will provide and when. The communication should also confirm the vendor’s point of contact for ongoing incident coordination and establish the communication cadence for updates. If your contract includes specific incident notification provisions, the vendor should be reminded of those obligations in the communication.
How do we build a vendor incident response protocol if we do not have one?
For each critical and high-tier vendor, the protocol development process starts with identifying the security and legal contacts at the vendor who would respond to a breach, as distinct from the account management contacts who handle day-to-day operations. The vendor is approached to agree on the mutual notification procedures: what each party will tell the other in the event of an incident, within what timeframe, and through what channel. The access restriction procedure is documented: specifically what access will be reviewed and potentially restricted, and who has the authority to make and execute that decision. The evidence handling expectations are defined: who will conduct forensic analysis of shared systems and data, how evidence will be preserved and documented, and what information will be shared between the parties. The completed protocol is reviewed and agreed by the vendor, stored in an accessible location, and included in the annual supplier risk review cycle.
The Bottom Line
When a vendor is breached, the clock starts before you know whether you are affected. The organizations that come through it well are the ones that already know what access the vendor holds, can restrict it fast, can search their own environment for signs the attacker came through, and know their own notification obligations start on awareness, not on confirmation. The difference between a controlled response and a scramble is almost always whether a vendor incident response protocol existed before the call came in. A structured supplier risk management program builds those protocols for your critical vendors in advance, so vendor breach response is a procedure you follow rather than one you invent under pressure.
About the author
David Chernitzky is Co-Founder and CEO of Armour Cybersecurity, a Toronto-based cybersecurity firm founded by military intelligence veterans and advised by senior leaders from PwC, KPMG, Deloitte, EY, and Mandiant. Armour serves more than 260 organizations across 52-plus industries, including finance, healthcare, technology, energy, legal, and government, with a 97 percent client retention rate.



